AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

MCP Tools With A Parameter Named "Config" Silently Broken By LangChain'S RunnableConfig Injection

When an MCP tool defines an input parameter named 'config' (or 'run_manager' or 'callbacks'), LangChain's StructuredTool invocation overwrites the user-supplied value with the internal RunnableConfig dict, causing silent data corruption and incorrect tool behavior.

highConfidence 92%LangChainAffected Vlangchain-Mcp-Adapters==0.2.2Affected Vlangchain-Core>=0.3.0,<0.4.0

Origin Analysis

LangChain's BaseTool.arun injects runtime parameters by matching the argument names of StructuredTool._arun. Since _arun has a parameter named 'config' (and 'run_manager'/'callbacks'), the injection logic unconditionally overwrites any user-provided tool input key with the same name. The MCP adapter passes through arbitrary MCP input schemas without sanitizing reserved names, leading to the collision.
1. Create an MCP tool with inputSchema properties containing a field named 'config' (string type). 2. Convert it using langchain_mcp_adapters.tools.convert_mcp_tool_to_langchain_tool(session, tool). 3. Invoke the resulting LangChain tool with arguments {'config': 'my_value', 'query': 'hello'}. 4. Observe that the underlying coroutine receives config as a RunnableConfig dict (with callbacks, tags, etc.) instead of the string 'my_value'.

Fixing Code Block

Edge Case Audit

This hotfix changes the public input schema for tools that use reserved names; existing clients expecting the original field name (e.g. 'config') will break. It is recommended only as an interim adapter-level workaround. If a future langchain-core version fixes the injection logic, the renaming may become unnecessary and could cause double-mapping. Rollback: revert to the original converter and upgrade langchain-core once the core bug is resolved. Also ensure the MCP session is safe for concurrent calls if the tool is invoked concurrently.

Ecosystem Topology